Cayman Islands Data Protection Act 2017 (DPA)
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Cayman DPA: Controller Obligations and Breach
s.16: where a personal data breach occurs, the data controller must, without undue delay and in any event within 5 days of becoming aware, notify the Ombudsman and any affected data subject.
- breach detection and assessment process
- records of notification to the Ombudsman and affected data subjects within the statutory time
- breach register
- breaches not notified to the Ombudsman
- affected individuals not notified
- notification beyond the statutory deadline
Cayman DPA: Data Protection Principles (Schedule 1)
Schedule 1, First Principle: personal data must be processed fairly and lawfully, and only if at least one Schedule 2 condition (and, for sensitive data, a Schedule 3 condition) is met, with specified information provided to the data subject.
- identified Schedule 2 (and Schedule 3 for sensitive) condition for each processing
- privacy/fair-processing notices providing the specified information
- processing without a Schedule 2/3 condition
- no fair-processing notice
Schedule 1, Second Principle: personal data must be obtained only for one or more specified lawful purposes and not further processed in a manner incompatible with those purposes.
- evidence the principle is met in processing operations
- records/policies demonstrating compliance
- data protection impact / processing records
- principle not demonstrably applied
- no records evidencing compliance
Schedule 1, Third Principle: personal data must be adequate, relevant and not excessive in relation to the purpose(s) for which they are processed (data minimisation).
- evidence the principle is met in processing operations
- records/policies demonstrating compliance
- data protection impact / processing records
- principle not demonstrably applied
- no records evidencing compliance
Schedule 1, Fourth Principle: personal data must be accurate and, where necessary, kept up to date.
- evidence the principle is met in processing operations
- records/policies demonstrating compliance
- data protection impact / processing records
- principle not demonstrably applied
- no records evidencing compliance
Schedule 1, Fifth Principle: personal data must not be kept for longer than is necessary for the purpose(s) for which they are processed.
- evidence the principle is met in processing operations
- records/policies demonstrating compliance
- data protection impact / processing records
- principle not demonstrably applied
- no records evidencing compliance
Schedule 1, Sixth Principle: personal data must be processed in accordance with the rights of data subjects under the Act.
- evidence the principle is met in processing operations
- records/policies demonstrating compliance
- data protection impact / processing records
- principle not demonstrably applied
- no records evidencing compliance
Schedule 1, Seventh Principle: appropriate technical and organisational measures must be taken against unauthorised or unlawful processing and against accidental loss, destruction of, or damage to personal data; processors must provide sufficient guarantees.
- appropriate technical and organisational security measures proportionate to risk
- contracts requiring processors to provide sufficient security guarantees
- security measures not proportionate to risk
- processor security guarantees not obtained
Schedule 1, Eighth Principle: personal data must not be transferred to a country or territory unless that country or territory ensures an adequate level of protection, subject to the Schedule 4 exceptions.
- adequacy assessment of destination country/territory
- reliance on a Schedule 4 transfer exception where applicable
- transfer without adequacy or a Schedule 4 basis
Cayman DPA: Enforcement and the Ombudsman
s.43: a person may complain to the Ombudsman that a data controller has contravened or is contravening the Act; the Ombudsman may investigate.
- process for responding to and cooperating with an Ombudsman complaint or investigation
- no process to respond to an Ombudsman complaint
s.47: a person aggrieved by an order, determination or decision of the Ombudsman may apply to the Grand Court for judicial review.
- awareness of judicial-review rights and process
s.55: the Ombudsman may impose a monetary penalty order on a data controller or processor for serious contraventions of the Act.
- awareness of monetary-penalty exposure
- process for responding to a monetary penalty order
- no process for responding to enforcement action
Cayman DPA: Exemptions
s.18: personal data are exempt from the provisions of the Act where the exemption is required for the purpose of safeguarding national security.
- documented basis for any national-security exemption relied upon
- exemption relied on without proper basis
s.31: further exemptions from the Act may be provided for by regulations; reliance on any such exemption must meet its conditions.
- analysis of any regulatory exemption relied upon and its conditions
- exemption misapplied
Cayman DPA: Rights of Data Subjects
s.10: a data subject may by notice require a data controller to cease, or not begin, processing that is causing or likely to cause unwarranted substantial damage or distress.
- process to receive and respond to s.10 notices
- s.10 notices not actioned
s.11: a data subject may by notice require a data controller to cease processing personal data for the purposes of direct marketing.
- marketing suppression list and opt-out mechanism
- marketing continued after opt-out
s.12: a data subject may require that decisions significantly affecting them are not based solely on automated processing, and is entitled to information about the logic.
- identification of solely-automated decisions
- mechanism to require human involvement and explain the logic
- solely-automated significant decisions without safeguards
s.14: a data subject may apply to the court for an order to rectify, block, erase or destroy inaccurate personal data (and related expressions of opinion).
- process to rectify, block, erase or destroy inaccurate data
- records of corrections and notifications to third parties
- inaccurate data not corrected on valid request
s.8: a data subject is entitled, on request, to be informed whether personal data are processed and to be given a description of and access to the data, the purposes, recipients and the source.
- subject-access-request handling process and records
- responses within the statutory timeframe
- access requests not honoured or late
Cayman DPA: Schedules - Conditions and Transfers
Schedule 2: at least one condition must be met for processing of general personal data to satisfy the First Principle (e.g. consent, contract, legal obligation, vital interests, public functions, legitimate interests).
- documented Schedule 2 condition for each general-data processing activity
- no Schedule 2 condition identified
Schedule 3: additional conditions that must be met (in addition to a Schedule 2 condition) to process sensitive personal data.
- documented Schedule 3 condition for each sensitive-data processing activity
- sensitive data processed without a Schedule 3 condition
Schedule 4: the circumstances in which a transfer of personal data to a country without adequate protection is nonetheless permitted (e.g. consent, contract, substantial public interest, legal proceedings).
- documented Schedule 4 basis for any transfer to a non-adequate country
- transfer to non-adequate country without a Schedule 4 basis
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Cayman Islands Data Protection Act 2017 (DPA) framework page.